2026-07-12 14:43:31 -07:00
|
|
|
import { describe, test, expect } from 'vitest';
|
|
|
|
|
import { NumberCounter } from './NumberCounter';
|
|
|
|
|
|
|
|
|
|
const toHtml = (NumberCounter as any).toHtml;
|
|
|
|
|
|
|
|
|
|
const counters = [
|
|
|
|
|
{ number: 150, suffix: '+', label: 'Projects' },
|
|
|
|
|
{ number: 50, suffix: '+', label: 'Clients' },
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
describe('NumberCounter.toHtml deterministic + unique scope ids (thread node id, no Math.random)', () => {
|
|
|
|
|
test('same node id -> identical output across calls (deterministic)', () => {
|
|
|
|
|
const { html: html1 } = toHtml({ counters }, '', 'node-nc1');
|
|
|
|
|
const { html: html2 } = toHtml({ counters }, '', 'node-nc1');
|
|
|
|
|
expect(html1).toBe(html2);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('different node ids -> distinct, non-colliding nc_ scopes (identical props, no collision)', () => {
|
|
|
|
|
const { html: html1 } = toHtml({ counters }, '', 'node-nc1');
|
|
|
|
|
const { html: html2 } = toHtml({ counters }, '', 'node-nc2');
|
|
|
|
|
const wrapId1 = html1.match(/<div id="(nc_[^"]+)"/)![1];
|
|
|
|
|
const wrapId2 = html2.match(/<div id="(nc_[^"]+)"/)![1];
|
|
|
|
|
expect(wrapId1).not.toBe(wrapId2);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('wrapper id, per-counter ids, and inline script agree on the same uid', () => {
|
|
|
|
|
const { html } = toHtml({ counters }, '', 'node-nc1');
|
|
|
|
|
const wrapId = html.match(/<div id="(nc_[^"]+)"/)![1];
|
|
|
|
|
expect(html).toContain(`id="${wrapId}_n0"`);
|
|
|
|
|
expect(html).toContain(`id="${wrapId}_n1"`);
|
|
|
|
|
expect(html).toContain(`var uid="${wrapId}"`);
|
|
|
|
|
expect(html).toContain('document.getElementById(uid)');
|
|
|
|
|
expect(html).toContain('document.getElementById(uid+"_n"+i)');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('no nodeId (legacy 2-arg call): still deterministic across repeated calls, not random', () => {
|
|
|
|
|
const { html: html1 } = toHtml({ counters }, '');
|
|
|
|
|
const { html: html2 } = toHtml({ counters }, '');
|
|
|
|
|
expect(html1).toBe(html2);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('two different node ids never collide even with default (no counters override) props', () => {
|
|
|
|
|
const { html: html1 } = toHtml({}, '', 'node-a');
|
|
|
|
|
const { html: html2 } = toHtml({}, '', 'node-b');
|
|
|
|
|
const wrapId1 = html1.match(/<div id="(nc_[^"]+)"/)![1];
|
|
|
|
|
const wrapId2 = html2.match(/<div id="(nc_[^"]+)"/)![1];
|
|
|
|
|
expect(wrapId1).not.toBe(wrapId2);
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-12 18:03:44 -07:00
|
|
|
|
|
|
|
|
describe('NumberCounter.toHtml counter.number is NOT runtime-type-checked -- must be sanitized before it reaches data-target', () => {
|
|
|
|
|
test('a malicious counter.number cannot break out of the data-target attribute to inject a <script> tag', () => {
|
|
|
|
|
const malicious = [
|
|
|
|
|
{ number: '150"><script>alert(1)</script>', suffix: '+', label: 'Evil' },
|
|
|
|
|
];
|
|
|
|
|
const { html } = toHtml({ counters: malicious }, '', 'node-nc-evil1');
|
|
|
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
|
|
|
expect(html).not.toContain('"><script>');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a malicious counter.number cannot break out of the data-target attribute to inject an onmouseover handler', () => {
|
|
|
|
|
const malicious = [
|
|
|
|
|
{ number: '150" onmouseover="alert(1)', suffix: '+', label: 'Evil' },
|
|
|
|
|
];
|
|
|
|
|
const { html } = toHtml({ counters: malicious }, '', 'node-nc-evil2');
|
|
|
|
|
expect(html).not.toContain('onmouseover=');
|
|
|
|
|
expect(html).not.toMatch(/data-target="150" onmouseover/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('normal numeric counter.number values still render as data-target="150"', () => {
|
|
|
|
|
const normal = [{ number: 150, suffix: '+', label: 'Projects' }];
|
|
|
|
|
const { html } = toHtml({ counters: normal }, '', 'node-nc-normal');
|
|
|
|
|
expect(html).toContain('data-target="150"');
|
|
|
|
|
});
|
|
|
|
|
});
|